Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
40 distinct techniques documented for this family, organized by ATT&CK tactic.
The PowerShell command executed via ClickFix downloads additional PowerShell code from an external server and runs it in the background.
The command used for extraction is as follows: "C:\Users\???\AppData\Roaming\Viqwo Stars Ci\Rotq App\UnRar.exe" x -p3809610121t -o+ ...
The sample requires user interaction to execute, triggered by the execution of the setup.msi file.
When a user clicks on the malicious URL in the email, they are redirected multiple times and ultimately connected to a malicious page disguised as a Cloudflare CAPTCHA screen.
The main purpose of the malware that is dropped by the Satacom downloader is to steal BTC from the victim’s account by performing web injections into targeted cryptocurrency websites. The malware attempts to do this by installing an extension for Chromium-based web browsers.
Persistence setup: Registering 'Run' and 'RunOnce'.
Finally, the PS script recursively searches for any link (.LNK) file in the above locations and modifies the “Target” parameter for all existing browser shortcuts with the flag “–load-extension=[pathOfExtension]” so that the shortcut will load the browser with the malicious extension installed.
The backdoor can execute native PE files using process injection and execute shellcode through Explorer.exe process injection.
Native PE execution includes 'RuntimeBroker.exe' process hollowing.
Persistence setup: Registering 'Run' and 'RunOnce'.
Finally, the PS script recursively searches for any link (.LNK) file in the above locations and modifies the “Target” parameter for all existing browser shortcuts with the flag “–load-extension=[pathOfExtension]” so that the shortcut will load the browser with the malicious extension installed.
LegionLoader sequentially decrypts encrypted shellcode and PE files it contains, then executes the final backdoor malware.
The malicious page is disguised as a Cloudflare CAPTCHA, while malicious URLs are presented as an official website or legitimate internal business system.
The backdoor can execute native PE files using process injection and execute shellcode through Explorer.exe process injection.
Native PE execution includes 'RuntimeBroker.exe' process hollowing.
This buffer is then decoded, revealing the shellcode... Another buffer in then created and data is copied to it using the rep movsb instruction. This buffer is then decoded, revealing the stage 2 executable.
Since the malware later attempts to execute the payload using rundll32, it is highly likely that the final payload is a DLL...
Within the MSI, two anti-sandbox mechanisms have been identified. The first anti-sandbox measure presents a button with the label “Please verify that you are not a robot.”. In one of the samples, it was observed that a virtual environment is detected through a feature of Advanced Installer.
For example, it has the ability to retrieve the victims’ addresses, obtain account information, bypass 2FA, and much more.
For example, it can extract information through the browser, such as the system information, cookies, browser history, screenshots of opened tabs, and even receive commands from the C2 server.
An HTTP GET request is sent to ipinfo[.]io/what-is-my-ip to compare the system's ASN type value with the 'hosting' string.
For example, it has the ability to retrieve the victims’ addresses, obtain account information, bypass 2FA, and much more.
Chrome information collection includes collecting browser history.
Within the MSI, two anti-sandbox mechanisms have been identified. The first anti-sandbox measure presents a button with the label “Please verify that you are not a robot.”. In one of the samples, it was observed that a virtual environment is detected through a feature of Advanced Installer.
The restored shellcode checks whether the current system corresponds to a virtualized environment, a remote environment, or an IP environment assigned by a hosting provider.
JavaScripts: requesting commands from the C2 (left pane) and taking screenshots (right pane)
The malicious extension has various JS scripts to perform browser manipulations while the user is browsing the targeted websites, including enumeration and manipulation with cryptocurrency websites.
The final backdoor registers infected-host information with C2 and receives commands through nfront.php, while nback.php reports command-execution results.
To do so, it performs a DNS request to don-dns[.]com through Google DNS (8.8.8.8, another decrypted string) and it queries for the TXT record.
The executed PowerShell command downloads additional PowerShell code from an external server; this then downloads a 7z compressed file containing LegionLoader.
244 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage loader distributed through fake Cloudflare CAPTCHA ClickFix lures, malicious wiki links, and spear-phishing emails. It uses PowerShell to retrieve additional stages, performs virtual-machine, remote-display, and hosting-ASN checks, decrypts embedded payloads, and loads a final C2-controlled backdoor. The backdoor can execute PE files, shellcode, PowerShell scripts, and MSI packages; inject into or hollow processes; establish Run/RunOnce persistence; collect Chrome legacy master keys, app-bound encryption keys, browser profiles, and history; and communicate with C2 using RC4 and Base64.
LegionLoader is referenced as infrastructure-associated malware in the delivery chain, with one Go-based variant contacting infrastructure associated with it.
An information-stealing payload delivered by OnionDrop.
A downstream payload delivered by OnionDrop. The analyzed sample used Donut-generated shellcode to unpack LegionLoader in memory; the payload dynamically resolves APIs, decrypts its RC4-protected C2 configuration, and communicates with gainmsg[.]com.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.